
Uber Technologies has been fined 290 million euros (approximately $324.6 million) by the Netherlands’ data-protection watchdog for transferring European drivers’ data to the United States without adequate protections. The Dutch Data Protection Authority (DPA) determined that Uber’s actions violated the European Union’s General Data Protection Regulation (GDPR), which imposes strict requirements on the handling and transfer of personal data.
The DPA’s investigation revealed that Uber had collected sensitive information from drivers in Europe, including photos, location data, identity documents, and even criminal and medical records. This data was transferred to U.S. servers without the necessary safeguards in place to ensure compliance with GDPR standards. Aleid Wolfsen, chairman of the Dutch Data Protection Authority, emphasized the severity of the breach, stating that Uber had failed to meet the GDPR’s requirements for data protection during these transfers.
In response, Uber announced its intention to appeal the fine, arguing that the data transfers occurred during a period of legal uncertainty regarding transatlantic data flows. This uncertainty stemmed from the European court’s 2020 decision to invalidate the Privacy Shield, a framework that had previously facilitated data transfers between the U.S. and the EU. It wasn’t until 2023 that the European Commission introduced the new EU-U.S. Data Privacy Framework, which reestablished a legal basis for such transfers.
Uber contends that despite the Privacy Shield being invalidated, its data practices remained compliant with GDPR throughout the period in question. The company also noted that it did not need to alter its data transfer processes when the new framework came into effect. An Uber spokesperson criticized the DPA’s decision as “flawed” and described the fine as “completely unjustified.” The appeals process is expected to take up to four years.
The case highlights the challenges faced by companies operating across borders during a time of significant legal ambiguity regarding data privacy. Critics argue that European and American businesses were left in a difficult position during the three-year gap between the invalidation of the Privacy Shield and the establishment of the new Data Privacy Framework. Alexandre Roure, head of policy at the Computer and Communications Industry Association in Europe, expressed concern over retroactive fines imposed by data protection authorities, particularly given the lack of clear guidance during the period of legal uncertainty.
The Dutch DPA’s investigation was prompted by complaints from more than 170 French drivers, with the Netherlands’ regulatory authority taking the lead due to Uber’s European headquarters being located in the country. The case underscores the ongoing scrutiny of data privacy practices in the tech industry, especially in light of stringent regulations like the GDPR.

Your First 10 AI Skills
10 practical AI skills, copy-paste prompts and a 7-day plan to start using AI with confidence.
Download the guide →